← back to case studies
On-prem security · Kerberos + mTLSProduction

Machine identity at scale

Kerberos implemented on premises and mTLS for server-to-server communication, establishing machine identity at large scale across a regulated on-prem fleet.

KerberosmTLSVault
architecturescroll to pan →
Kerberos KDCon-prem authService AworkloadService BworkloadauthauthmTLS server-to-serverMachine identityissued at scale

Problem

Server-to-server communication in a regulated on-prem environment needed strong authentication and encryption, with machine identity managed consistently across a large fleet.

My role

Helped implement Kerberos on premises, managed mTLS for server-to-server communication, and implemented machine identity at large scale.

What shipped

  • +Kerberos implemented on premises
  • +mTLS for server-to-server communication
  • +Machine identity established across the fleet

Outcome

  • Authenticated, encrypted server-to-server communication
  • Machine identity managed consistently at large scale